Fall 2014 Schedule

Date
Chapter
Coverage
Readings
Assignment
Due Date
08/20/2014
Introduction




08/27/2014
Chapter 1
The Threat Environment
Read the 4 Threat Environment articles and be prepared to discuss in class.


09/03/2014
Readings:
COSO, COBIT
From the Frameworks & Standards page, read:* Internal Control - Integrated Framework (1992)


09/10/2014
Chapter 2
Planning & Policy
We will be discussing an alternative Risk Assessment method OCTAV Alegro, you can read more here.


09/17/2014
Module A
Networking Concepts



09/24/2014
No Class




10/01/2014
Chapter 3
Cryptography
Read the Cryptography Readings from the Class Readings page


10/08/2014
Chapter 4
Secure Networks



10/10/2014 to 10/14/2014
Exam 1 (Chapter 1-4, Module A, Readings)




10/15/2014
Chapter 5
Access Controls



10/22/2014
Readings
Passwords
Read the required readings from the Password section of the Class Readings
Access Control Simulation
10/29/2014
10/29/2014
Chapter 6
Firewalls



11/05/2014
Chapter 7 & 8
Host Hardening & Application Security
Read the required Application Hardening articles section of the Class Readings


11/12/2014
Chapter 9 & 10
Data Protection & Incident and Disaster Response
Read, The Future of Incident Response, by Bruce Schneier


11/19/2014
Readings
SOX IT Readings
Read the required readings from the IT Control and SOX section of the Class Readings
Security in the News
11/26/2014
11/26/2014
Readings
Readings
From the Frameworks & Standards page, read:* Enterprise Risk Management - Integrated Framework (2004)
    1. Cyberattack's abound yet companies tell SEC losses are few By Chris Strohm, Eric Engleman and Dave Michaels - Apr 3, 2013)
    2. Companies Hacked by Chinese Didn’t Disclose Attacks to Investors By By Chris Strohm, Dave Michaels and Sonja Elmquist - May 21, 2014)
    3. CF Disclosure Guidance: Topic No. 2 S.E.C. (This guidance provides the Division of Corporation Finance's views regarding disclosure obligations relating to cybersecurity risks and cyber incidents)
    4. SEC Cybersecurity Roundtable Archive Webcast
    5. SEC OCIE Cybersecurity Initiative (April 15, 2014)

    1. AICPA Top 5 Cybercrimes (2013)

    1. ERM for cloud computing (COSO)


11/28/2014 to 12/03/2014
Final Exam (5-10) and Readings